Re: [fw-wiz] Benefit of firewall over NAT-only 'protected' network

ark_at_eltex.net
Date: 05/28/03

  • Next message: Paul Robertson: "Re: [fw-wiz] Benefit of firewall over NAT-only 'protected' network"
    To: Paul Robertson <proberts@patriot.net>
    Date: Wed, 28 May 2003 13:28:14 +0400
    

    nuqneH,

    What's wrong with irc? It is a good communication tool.
    It is reasonable to deny DCC file transfers, though, and there should
    be no non-approved clients because of security bugs. Select one or two
    clients per platform that to be allowed in your office, deny DCC
    send/receive, inform users about dangers of installing custom scripts,
    maintain a list of allowed servers/networks, keep an
    eye on vulnerability database and i am pretty sure risk from using
    Outlook or IE is more important in this situation.

    Even "out of the box" irc is not more insecure than widely-used ICQ.
    I even encourage users to use corporate IRC server as generic
    messaging tool. It is far better than using ICQ (with mirabilis servers
    usually!) as _really many_ companies that have no own IM system do.

    On Tue, May 27, 2003 at 10:50:28PM -0400, Paul Robertson wrote:

    > That's a silly and mostly specious pre-requisite. For instance, most
    > small office users have *no* need for IRC, and given that IRC is *the*
    > major control vector for trojaned machines, why the heck would you allow it
    > outbound from a small office? Nuke 6667/tcp outbound and you decrease the
    > chance of being owned rather significantly, and you break less than 1/2 of
    > 1% of SOHO users.
    >
     
                                         _ _ _ _ _ _ _
     {::} {::} {::} CU in Hell _| o |_ | | _|| | / _||_| |_ |_ |_
     (##) (##) (##) /Arkan#iD |_ o _||_| _||_| / _| | o |_||_||_|
     [||] [||] [||] Do i believe in Bible? Hell,man,i've seen one!
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Paul Robertson: "Re: [fw-wiz] Benefit of firewall over NAT-only 'protected' network"

    Relevant Pages

    • Re: [Offtopic?] IRC blocked at school
      ... IRC clients. ... #debian and #debian-eeepc ... I doubt they block the clients, but rather the ports used by said ... To UNSUBSCRIBE, email to debian-user-REQUEST@xxxxxxxxxxxxxxxx ...
      (Debian-User)
    • Re: IRC protocols and insecurity
      ... IRC network is great choice, i have been on IRC for some years, its security ... If you are using mIRC clients with some of its powerful scripting engine, ... Ethical Hacking at the InfoSec Institute. ...
      (Pen-Test)
    • Re: [Offtopic?] IRC blocked at school
      ... IRC clients. ... Is there any good way to tunnel or encrypt my data, ... I doubt they block the clients, but rather the ports used by said ...
      (Debian-User)
    • Re: Stripped down versions of software
      ... > I'm installing debian on a 486 laptop, and want to use it for X, IRC, www and ... > RAM, and which IRC, WWW and email clients would also be good to use here? ... google for what type of memory your laptop can take and ...
      (Debian-User)
    • Re: [Full-Disclosure] Why is IRC still around?
      ... IRC is a great communication tool that has grown and evolved over the ... There will always be a medium for "questionable activities" ... and illegal acts to propagate regardless of what communication link ... > 4) That many organized DoS attacks through PC zombies are initiated through IRC? ...
      (Full-Disclosure)